IBM Spectrum Protect Plus¶à¸ö·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-03-10·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-4210£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2020-4213£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2020-4222£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2020-4212£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2020-4211£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
IBM Spectrum Protect Plus 10.1.0-10.1.5
·ì϶¸ÅÊö
IBM Spectrum Protect PlusÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»Ì×Êý¾Ý±£»¤Æ½Ì¨¡£¸Ãƽ̨ΪÆóÒµÌṩµ¥Ò»½ÚÔìºÍÖÎÀíµã£¬²¢Ö§³Ö¶ÔËùÓйæÄ£µÄÐé¹¹¡¢ÎïÀíºÍÔÆ»·¾³½øÐб¸·ÝºÍ¸´Ô¡£
½üÈÕ£¬ZDI¹«¿ªÅû¶ÁËIBM Spectrum Protect Plus²úÆ·ÖеÄ5¸öÑϳÁ·ì϶¡£ÕâЩ·ì϶¶¼´æÔÚÓÚAdministrative Console Framework serviceÖУ¬¹¥»÷ÕßÀûÓÃÕâЩ·ì϶¶¼ÎÞÐèÉí·ÝÈÏÖ¤¡£¸ÅÊöÈçÏ£º
CVE-2020-4210
·ì϶ԴÓÚÔÚ½«Óû§ÌṩµÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬Î´Äܰ²Í×µØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄHTTPºÅÁîÀûÓø÷ì϶ÔÚÊÜÓ°ÏìµÄIBM Spectrum Protect PlusÉÏÖ´ÐÐËÁÒâ´úÂë¡£
CVE-2020-4213
·ì϶ԴÓÚÔÚ½âÎöusername²ÎÊýµÄʱ³½£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬Î´Äܰ²Í×µØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£Èç³É¹¦ÀûÓø÷ì϶£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚÖÎÀíÔ±µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£
CVE-2020-4222
·ì϶ԴÓÚÔÚ½âÎöpassword²ÎÊýʱ£¬Î´Äܰ²Í×µØÑéÖ¤Óû§Ìá½»µÄ×Ö·û´®¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚrootµÄ¸ßµÍÎÄÖÐÖ´ÐдúÂë¡£
CVE-2020-4212
·ì϶ԴÓÚÔÚ½âÎöhfpackage²ÎÊýʱ£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬Î´Äܰ²Í×µØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£Èç³É¹¦ÀûÓø÷ì϶£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚrootµÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£
CVE-2020-4211
·ì϶ԴÓÚÔÚ½âÎöhostname²ÎÊýʱ£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬Î´Äܰ²Í×µØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£Èç³É¹¦ÀûÓø÷ì϶£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚrootµÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£
·ì϶ÑéÖ¤
ÔÝÎÞPoC/EXP¡£
½¨¸´½¨Òé
Ŀǰ¹Ù·½ÒѰ䲼²¹¶¡½¨¸´·ì϶£¬Á´½Ó£ºhttp://www.ibm.com/support/docview.wss?uid=ibm11072392¡£
²Î¿¼Á´½Ó
https://www.zerodayinitiative.com/advisories/ZDI-20-270/
https://www.zerodayinitiative.com/advisories/ZDI-20-271/
https://www.zerodayinitiative.com/advisories/ZDI-20-272/
https://www.zerodayinitiative.com/advisories/ZDI-20-273/
https://www.zerodayinitiative.com/advisories/ZDI-20-274/


¾©¹«Íø°²±¸11010802024551ºÅ